Lucene search

K
cveMitreCVE-2014-9300
HistoryDec 07, 2014 - 9:59 p.m.

CVE-2014-9300

2014-12-0721:59:01
CWE-352
mitre
web.nvd.nist.gov
30
cve-2014-9300
csrf
vulnerability
alfresco
cmis
authentication
hijacking
unauthorized urls
user credentials
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

61.3%

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to hijack the authentication of users for requests that access unauthorized URLs and obtain user credentials via a URL in the url parameter.

Affected configurations

Nvd
Node
alfrescoalfrescoRange5.0.acommunity
VendorProductVersionCPE
alfrescoalfresco*cpe:2.3:a:alfresco:alfresco:*:*:*:*:community:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

61.3%

Related for CVE-2014-9300